Last Updated: January 2026
Summary: 266bat ("we", "us", "our") is committed to protecting the privacy of every player who uses our platform. This Privacy Policy describes our data practices in full. By registering a 266bat account or using any of our services, you acknowledge that you have read and understood this policy.
01 Introduction
This Privacy Policy applies to all personal data collected and processed by 266bat in connection with the operation of the 266bat website at https://266bat.app and all associated services, including sports betting, live casino, slots, crash games, and customer support functions. It covers data collected from players located in Bangladesh as well as from visitors who browse the platform without registering.
266bat takes its responsibilities as a data controller seriously. We process personal data only for lawful purposes, retain it only for as long as necessary, and apply appropriate technical and organisational safeguards to keep it secure. This policy is intended to be clear, specific, and transparent — not a document designed to obscure how we handle your information.
This Privacy Policy should be read alongside our Terms & Conditions and our Responsible Gaming policy. Together, these documents govern your relationship with 266bat as a registered player.
02 Data We Collect
266bat collects the following categories of personal data, depending on how you interact with the platform:
| Category |
Examples |
When Collected |
| Identity Data |
Full legal name, date of birth, national ID or passport number |
Registration & KYC verification |
| Contact Data |
Mobile number, email address, residential address (Dhaka, Chittagong, Sylhet, etc.) |
Registration & account updates |
| Financial Data |
bKash/Nagad/Rocket wallet numbers, bank account details, transaction records |
Deposits, withdrawals & KYC |
| Technical Data |
IP address, browser type, device type, operating system, session timestamps |
Automatically on site access |
| Usage Data |
Pages visited, games played, bets placed, session duration, click patterns |
Automatically during platform use |
| Communications Data |
Support chat transcripts, email correspondence, complaint records |
When you contact support |
| Marketing Preferences |
Opted-in communication channels, preferred bonus types, language preferences |
Account settings & consent forms |
Sensitive Data: 266bat does not intentionally collect special categories of sensitive personal data (such as health data, religious beliefs, or political opinions). If such data is incidentally disclosed during a support interaction, it will not be processed for any purpose beyond resolving the immediate matter.
03 How Data Is Collected
266bat collects personal data through three primary channels:
- Direct Collection: Data you actively provide when creating an account, submitting identity verification documents, making a deposit or withdrawal request, completing a promotional opt-in, or contacting our customer support team.
- Automated Collection: Technical and usage data collected automatically via server logs, cookies, and similar tracking technologies when you browse the 266bat website or use the platform. This data is collected regardless of whether you are logged in to an account.
- Third-Party Sources: In limited circumstances, 266bat may receive data from third parties to support identity verification, fraud prevention, or payment processing. These third parties are subject to their own privacy obligations and are selected on the basis of their compliance standards. Examples include payment processors handling bKash and Nagad transactions, and identity verification service providers.
04 How We Use Your Data
266bat uses your personal data only for the following lawful purposes. Against each purpose, we have identified the legal basis on which we rely:
- Account Creation and Management — To register your account, verify your identity, manage your balance, and provide you with access to all 266bat services. Legal basis: Contract performance.
- Processing Financial Transactions — To process your deposits and withdrawals via bKash, Nagad, Rocket, Upay, and connected banking partners, and to maintain accurate financial records. Legal basis: Contract performance; legal obligation.
- Fraud Prevention and Security — To detect, investigate, and prevent fraudulent activity, money laundering, and other illegal conduct on the platform. Legal basis: Legitimate interests; legal obligation.
- Responsible Gaming Compliance — To monitor gameplay patterns for signs of problem gambling, apply self-exclusion or cooling-off periods when requested, and fulfil our duty of care to players. Legal basis: Legitimate interests; legal obligation.
- Customer Support — To respond to your enquiries, resolve complaints, and improve the quality of our support services. Legal basis: Contract performance; legitimate interests.
- Platform Improvement — To analyse usage patterns, identify technical issues, test new features, and improve the overall 266bat player experience. Legal basis: Legitimate interests.
- Marketing Communications — To send you promotional offers, bonus notifications, and platform updates, but only where you have provided explicit opt-in consent to receive such communications. Legal basis: Consent.
- Legal and Regulatory Compliance — To meet any obligations imposed by applicable laws or competent authorities, including record-keeping and reporting requirements. Legal basis: Legal obligation.
No Automated Decision-Making: 266bat does not make decisions about your account — including account restrictions or closures — solely through automated means without human review. Where automated tools flag an account for review, a member of our compliance team will assess the matter before any material action is taken.
05 Sharing Your Data
266bat does not sell, rent, or trade your personal data. We share your data only in the following limited and necessary circumstances:
- Payment Processors: We share financial data with certified payment processors (including the operators of bKash, Nagad, Rocket, and Upay integrations, as well as partnered banks such as Dutch-Bangla Bank, City Bank, and BRAC Bank) strictly to facilitate your deposits and withdrawals. These processors are contractually bound to handle your data securely and only for the stated transaction purpose.
- Game Providers: To allow you to play games supplied by third-party providers such as Evolution Gaming, Pragmatic Play, NetEnt, and Spribe, certain technical identifiers (such as a session token or anonymised player ID) are shared with the relevant game provider. These providers do not receive your full identity or financial data.
- Identity Verification Services: Where KYC verification is required, your identity documents and personal details may be shared with accredited identity verification providers. These providers operate under strict data processing agreements.
- Legal Authorities: 266bat may disclose personal data to law enforcement, regulatory bodies, or other competent authorities where required to do so by applicable law, court order, or legitimate regulatory request. We will always seek legal advice before making disclosures beyond what is strictly required.
- Business Transfers: In the event of a merger, acquisition, or sale of all or part of 266bat's operations, player data may be transferred to the acquiring entity. In such circumstances, players will be notified in advance and their data will remain protected under equivalent terms.
06 Data Retention
266bat retains personal data only for as long as it is necessary for the purpose for which it was collected, or as required by applicable law. The following general retention periods apply:
- Account Data: Retained for the duration of your active account relationship with 266bat, plus a period of 5 years following account closure to meet legal and regulatory record-keeping requirements.
- Transaction Records: Financial transaction records are retained for a minimum of 5 years from the date of the transaction in accordance with financial record-keeping obligations.
- KYC Documentation: Identity verification documents are retained for a minimum of 5 years following the completion of the verification process or account closure, whichever is later.
- Support Communications: Customer support records, including chat transcripts and email correspondence, are retained for up to 3 years from the date of the interaction.
- Technical and Usage Data: Log files and anonymised usage analytics are retained for up to 24 months, after which they are deleted or fully anonymised.
- Marketing Data: Marketing preference data and opt-in consent records are retained until you withdraw consent or for a maximum of 3 years from the date of last engagement, whichever comes first.
When data reaches the end of its retention period, it is securely deleted or anonymised in a manner that prevents recovery or re-identification.
07 Security Measures
266bat implements a layered approach to data security, combining technical controls, organisational policies, and regular independent assessments to protect personal data against unauthorised access, loss, destruction, or alteration.
- SSL/TLS Encryption: All data transmitted between your device and the 266bat platform is encrypted in transit using industry-standard SSL/TLS protocols. The padlock icon in your browser confirms that your connection is secure.
- Encrypted Data Storage: Sensitive data at rest — including identity documents and financial records — is stored in encrypted form on secured servers. Encryption keys are managed under strict access control procedures.
- Access Controls: Access to player personal data within 266bat's internal systems is restricted on a strict need-to-know basis. Staff members are granted only the minimum level of data access required to perform their role.
- Two-Factor Authentication: 266bat supports two-factor authentication (2FA) for player accounts and enforces it for internal administrative access to player data systems.
- Regular Security Reviews: Our platform undergoes regular security assessments, including vulnerability scanning and penetration testing, to identify and remediate potential weaknesses before they can be exploited.
- Incident Response: In the event of a data breach that poses a risk to player rights and freedoms, 266bat will notify affected players without undue delay and will take immediate steps to contain and remediate the breach.
Your Responsibility: The security of your 266bat account also depends on you. Choose a strong, unique password and never share your login credentials with anyone. 266bat will never ask for your password via email, chat, or any other communication channel. If you receive such a request, treat it as fraudulent and report it to our support team immediately.
08 Cookies & Tracking Technologies
266bat uses cookies and similar tracking technologies to operate the platform effectively, remember your preferences, and analyse how players use the site. The following categories of cookies are in use:
- Strictly Necessary Cookies: These cookies are essential for the platform to function. They enable core features such as session management, login state, and security. These cookies cannot be disabled without breaking platform functionality.
- Functional Cookies: These cookies remember your preferences, such as your preferred language, display settings, and recently visited sections of the platform, so you do not have to re-configure them on each visit.
- Analytics Cookies: These cookies collect anonymised data about how visitors interact with the 266bat platform — for example, which pages are visited most frequently and how long sessions last. This data is used to improve platform design and performance. Analytics data is not linked to any identifiable individual.
- Session Cookies: Short-lived cookies that exist only for the duration of your browser session and are deleted automatically when you close your browser. Used primarily for login session management and bet slip persistence.
You can manage cookie preferences through your browser settings. Please note that disabling strictly necessary cookies will impair your ability to use the 266bat platform. 266bat does not use third-party advertising or retargeting cookies.
09 Your Rights
As a 266bat player, you have the following rights in relation to your personal data. To exercise any of these rights, contact our support team at [email protected] with the subject line "Data Rights Request" and your registered account details.
- Right of Access: You have the right to request a copy of the personal data that 266bat holds about you. We will provide this in a clear, structured format within a reasonable timeframe.
- Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data held on your account. Minor corrections (such as updating a phone number) can be made directly in your account settings.
- Right to Erasure: You have the right to request deletion of your personal data in certain circumstances — for example, where the data is no longer needed for the purpose it was collected, or where you withdraw consent and no overriding legal basis applies. Please note that certain data must be retained to meet legal obligations even after account closure.
- Right to Restriction: You have the right to request that processing of your data be restricted in certain circumstances, such as while a dispute about data accuracy is being resolved.
- Right to Portability: You have the right to receive personal data that you have actively provided to 266bat in a structured, machine-readable format, and to request that it be transmitted to another service provider where technically feasible.
- Right to Withdraw Consent: Where processing is based on your consent (such as marketing communications), you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
- Right to Object: You have the right to object to processing of your personal data where that processing is based on legitimate interests. 266bat will consider your objection and cease processing unless there are compelling legitimate grounds that override your interests.
We will respond to all data rights requests within 30 days. In complex cases, this period may be extended by a further 30 days, in which case we will notify you of the extension and the reason for it.
10 Minors & Age Verification
The 266bat platform is strictly intended for adults aged 18 and above. We do not knowingly collect personal data from individuals under the age of 18. Age verification is a mandatory step during the 266bat registration process, and additional verification checks may be performed at any time during the account lifecycle.
Underage Account Discovery: If 266bat discovers or receives credible notification that a registered account belongs to a person under 18 years of age, the account will be suspended immediately. Any deposits made will be refunded and any winnings generated will be forfeited. The personal data associated with the underage account will be handled in accordance with applicable child data protection principles.
If you are a parent or guardian and believe that a minor in your care has registered a 266bat account, please contact us immediately at [email protected]. We will treat all such reports with the highest priority and take immediate action.
11 Policy Changes
266bat reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, legal requirements, or platform operations. The "Last Updated" date at the top of this page will always reflect the most recent revision.
For material changes — those that significantly affect how we process your personal data or alter your rights — 266bat will provide advance notice via your registered mobile number or email address at least 7 days before the changes take effect. For minor or clarificatory changes, the updated policy will be published on this page without prior individual notification.
Your continued use of the 266bat platform following the effective date of any revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with any material change, you may close your account by contacting support prior to the effective date.